Privacy Policy
Last updated: 2026-07-01
The short version
- The desktop app runs on your machine. We never see your code, your brain files, or your Claude Code prompts.
- Brain Dreaming + Ask synth call Anthropic directly from your machine using your own API key. The Anthropic call never proxies through us.
- If you sign in to repoops.ai we store the minimum needed to bill you and run a hosted team (name, email, organization, billing identifiers, hashed device IDs).
- You can export or delete your hosted-account data at any time via /account/export and /account/delete.
1. What we collect
1.1 Desktop app (local only)
Nothing leaves your machine unless you explicitly bind the install to a hosted team. The desktop app reads files under repos you add and writes a local SQLite database in your data directory. No telemetry is transmitted in the default config.
1.2 repoops.ai (hosted)
If you sign in:
- Account fields: name, email, organization name, OAuth provider IDs (Google/GitHub), authentication tokens, billing customer ID.
- Billing: Stripe customer ID, subscription IDs, plan, seat counts, invoice history. Card numbers stay with Stripe.
- Team telemetry (Solo Hosted / Team tiers, opt-in): redacted Claude Code session metadata (model, tokens, cost, duration) - never prompts or completions.
- Server-side errors: request URL, error message, stack trace, hashed user ID. Sent to Sentry. No request body, no headers, no cookies.
- Product analytics (opt-in via cookie banner): page views, button clicks, anonymous session IDs, and (when you accept) Sentry Session Replay - a masked recording of your own session for debugging, with text and inputs masked by default. Sent to PostHog, Google Analytics, Vercel Web Analytics, and Sentry. None of these load until you accept; “Reject all” keeps them all off.
- Operational logs: Vercel access logs (IP, user agent, response code) retained 30 days for debugging and abuse response.
1.3 Cookies
We use three kinds of cookies. The first kind is set automatically; the third requires your consent via the cookie banner.
- Strictly necessary (session cookie, CSRF token, billing return URL) - exempt from consent under GDPR / PECR.
- Authentication (NextAuth session + refresh) - set after you sign in. Exempt from consent because you explicitly authenticated.
- Product analytics (PostHog, Google Analytics, Vercel Web Analytics, Sentry Session Replay) - set only after you accept analytics via the cookie banner. One click rejects all.
2. What we never see
- Your source code.
- The contents of your
.claude/brain/files (unless you opt in to publish a brain page). - Your Anthropic prompts or completions.
- Your local Claude Code transcripts.
3. Retention
- Free local desktop: no hosted account record; nothing leaves your machine unless you bind to a hosted tier.
- Solo Hosted / Team: telemetry retained 90 days; audit log retained 365 days; billing records 7 years (US tax requirement).
- Enterprise: configurable per the DPA.
- Deletion grace period: 30 days after you submit a delete request, during which the action is reversible by emailing support@repoops.ai.
4. Sub-processors
| Provider | Role | Region |
|---|---|---|
| Neon | Postgres database hosting | US-East |
| Vercel | Application + edge hosting; Web Analytics (opt-in via cookie banner) | Global |
| Stripe | Payments + subscription billing | US/EU |
| Resend | Transactional email | US |
| PostHog | Product analytics (opt-in via cookie banner) | US |
| Google Analytics | Web analytics (opt-in via cookie banner) | US |
| Sentry | Server-side error reporting; Session Replay (opt-in via cookie banner) | US/EU |
| Anthropic | Claude API - BYOK, customer's own sub-processor on every tier | US |
See the Data Processing Agreement for contractual terms with each sub-processor.
5. Your rights (GDPR / UK GDPR / CCPA)
- Access & portability: /account/export returns a JSON dump within minutes.
- Erasure: /account/delete queues a 30-day reversible delete.
- Rectification: edit your name + email at /account.
- Objection / restriction: email support@repoops.ai.
- Complaint: you can lodge a complaint with your local supervisory authority (e.g. ICO in the UK, CNIL in France).
6. International transfers
Our primary infrastructure is in the United States. For EU/UK customers, we rely on the Standard Contractual Clauses (SCCs) included in the DPAand on each sub-processor’s own SCC commitments.
7. Children
RepoOps is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal data, email support@repoops.aiand we’ll delete it.
8. Changes
Material changes will be posted here with at least 14 days’ notice to account holders by email.
See also: Terms of Service · Data Processing Agreement · Refund & cancellation policy.